Skip to content

Hide Navigation Hide TOC

GOLD BURLAP (d34ca487-1613-4ee5-8930-2ac8a60f945f)

GOLD BURLAP is a group of financially motivated criminals responsible for the development of the Pysa ransomware, also referred to as Mespinoza. Pysa is a cross-platform ransomware with known versions written in C++ and Python. As of December 2020, approximately 50 organizations had reportedly been targeted in Pysa ransomware attacks. The operators leverage 'name and shame' tactics to apply additional pressure to victims. As of January 2021, CTU researchers had found no Pysa advertisements on underground forums, which likely indicates that it is not operated as ransomware as a service (RaaS).

Cluster A Galaxy A Cluster B Galaxy B Level
GOLD BURLAP (d34ca487-1613-4ee5-8930-2ac8a60f945f) Threat Actor Mespinoza (68a7ca8e-2902-43f2-ad23-a77b4c48221d) Malpedia 1
GOLD BURLAP (d34ca487-1613-4ee5-8930-2ac8a60f945f) Threat Actor MimiKatz (588fb91d-59c6-4667-b299-94676d48b17b) Malpedia 1